Malware

Graftor.116390 information

Malware Removal

The Graftor.116390 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.116390 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.116390?


File Info:

name: 39FE723FBDB70C7985E2.mlw
path: /opt/CAPEv2/storage/binaries/228b7b48c3b5cd03bddb675bbd38e51cc1d4382ec0826c8ac98e22bbe107c01b
crc32: D3E7A5D0
md5: 39fe723fbdb70c7985e216340b017be9
sha1: 29f05e41217d7eab2d7d6c6249f056abfd0cfebf
sha256: 228b7b48c3b5cd03bddb675bbd38e51cc1d4382ec0826c8ac98e22bbe107c01b
sha512: d5d18d08497fdd056ebb3ad5d6a31adc93c54fcb935bbc4580f9d1090081f05cc9c5dc95d7bb7f6977525185f164cf6f1b707f99471681bb041d61a326c5cd87
ssdeep: 6144:cAyeLyt9VqV5LVSgadCbVCBuBK44XuAWIuMp2:/Y9VqVmdCb98m3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1124412F6B6C91672F69149F336E4EBBB492F8B95493444849920F98CF5307D48E3B382
sha3_384: e290d469f4b8424bfcf635d668ff5bdfce83185dd1451e2763400c06649169085338cce02e7ba55fbc3069eae2df7e3f
ep_bytes: 558bec6aff68e851400068e820400064
timestamp: 2013-09-26 16:39:27

Version Info:

0: [No Data]

Graftor.116390 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.116390
FireEyeGeneric.mg.39fe723fbdb70c79
ALYacGen:Variant.Graftor.116390
MalwarebytesMalware.Heuristic.1001
ZillyaTrojan.Kryptik.Win32.408103
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojanPSW:Win32/Kryptik.2ac20a0b
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Trojan.TIRW-1375
ESET-NOD32a variant of Win32/Kryptik.BLJY
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.116390
NANO-AntivirusTrojan.Win32.Zbot.croebf
SUPERAntiSpywareTrojan.Agent/Gen-BetaBot
AvastWin32:Injector-BLV [Trj]
SophosMal/BadCert-Gen
F-SecureHeuristic.HEUR/AGEN.1359054
DrWebTrojan.Betabot.1
VIPREGen:Variant.Graftor.116390
TrendMicroTROJ_SPNR.0BJF13
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.116390 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.116390
JiangminTrojanDropper.Injector.asry
GoogleDetected
AviraHEUR/AGEN.1359054
Antiy-AVLTrojan/Win32.Tgenic
XcitiumMalware@#381g84jelodgj
ArcabitTrojan.Graftor.D1C6A6
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R84399
Acronissuspicious
McAfeePWSZbot-FIP!39FE723FBDB7
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.0BJF13
RisingStealer.Zbot!8.109D7 (TFE:1:JXkTmC7abIQ)
YandexTrojan.GenAsa!JO2nCEDTmiY
IkarusTrojan.SuspectCRC
FortinetW32/Zbot.AAO!tr
BitDefenderThetaGen:NN.ZexaF.36196.qqX@aS1F7Np
AVGWin32:Injector-BLV [Trj]
Cybereasonmalicious.fbdb70
DeepInstinctMALICIOUS

How to remove Graftor.116390?

Graftor.116390 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment